×
Government

America's FDA Wants to Update Its Definition of 'Healthy'. The Food Industry Doesn't (msn.com) 221

America's public health-protecting Food and Drug Administration wants to update its definition of "healthy" for purposes of product labeling.

But the Washington Post reports dozens of food manufacturers are now "claiming the new standards are draconian and will result in most current food products not making the cut, or in unappealing product reformulations." Under the proposal, manufacturers can label their products "healthy" only if they contain a meaningful amount of food from at least one of the main food groups such as fruit, vegetable or dairy, as recommended by federal dietary guidelines. They must also adhere to specific limits for certain nutrients, such as saturated fat, sodium and added sugars.

It's the added sugar limit that has been the sticking point for many food executives. The FDA's previous rules put limits around saturated fat and sodium but did not include limits on added sugars.

The Consumer Brands Association, which represents 1,700 major food companies from General Mills to Pepsi, wrote a 54-page comment to the FDA in which it stated the proposed rule was overly restrictive and would result in a framework that would automatically disqualify a vast majority of packaged foods.... The proposed rule, if finalized, they said, would violate the First Amendment rights of food companies and could harm both consumers and manufacturers. The Sugar Association has an issue with the added sugar limit; Campbell Soup is more focused on that sodium....

Virtually every part of the food industry appeared disgruntled (here are the 402 comments about the proposed rule). Baby food company Happy Family Organics said the proposed rule probably would lead to an unintended exclusion of some nutrient-rich products. And the American Cheese Society took a more philosophical approach, saying the word "healthy" isn't that helpful on a label and should be used in a complete diet or lifestyle context rather than in a nutrient or single food-focused context.

The FDA estimates that up to just 0.4% of people who try to follow their guidelines would be swayed by the word "healthy" in their long-term food-purchasing decisions, according to the article. It's a position supported by a research paper in the Journal of Public Policy and Marketing analyzing hundreds of international studies on the effectiveness of front-of-package nutrition labeling.

"The authors found that the most effective means of conveying nutrition information is a graphic warning label, as has been adopted in Chile, Peru, Uruguay, Mexico and Israel. In Chile, black warning labels shaped like stop signs are required for packaged food and drinks that exceed, per 100 grams: 275 calories, 400 milligrams of sodium, 10 grams of sugar or four grams of saturated fats."
Government

Texts from Binance Reveal Plan to Elude US Authorities (livemint.com) 78

Reuters writes: Binance, one of the world's largest cryptocurrency exchanges, developed a plan to avoid the threat of prosecution by U.S. authorities as it started an American entity in 2019, the Wall Street Journal reported on Sunday.
The Wall Street Journal reports: Any lawsuit from U.S. regulators would be like "nuclear fall out" for Binance's business and its officers, a Binance executive warned colleagues in a 2019 private chat. Worried about the threat of prosecution, Binance set out on a plan to neutralize U.S. authorities, according to messages and documents from 2018 to 2020 reviewed by The Wall Street Journal as well as interviews with former employees.

The strategy centered on building a bare-bones American platform, Binance.US, that would license Binance's technology and brand but otherwise appear to be wholly independent of Binance.com. It would shield from U.S. regulators' scrutiny the larger Binance.com exchange, which would exclude U.S. users. But Binance and Binance.US have been much more intertwined than the companies have disclosed, mixing staff and finances and sharing an affiliated entity that bought and sold cryptocurrencies, according to the interviews and the messages and documents reviewed by the Journal. Binance developers in China maintained the software code supporting Binance.US users' digital wallets, potentially giving Binance access to U.S. customer data.

If U.S. regulators conclude that these links mean Binance has control over a U.S. company, they could claim the power to police Binance's entire business, which, to many investors, has been a black box since the start. This would also put Binance's billionaire founder and chief executive, Changpeng Zhao, and his finances under closer scrutiny.... Developers in Shanghai maintained key software functions at Binance.US at least through the summer of 2021, the Journal has reported. The Shanghai developers' contracts were with Binance, not with the U.S. platform, according to a person familiar with the agreements.

Crime

Sam Bankman-Fried is Under House Arrest - at Stanford. Students are Fascinated (msn.com) 50

FTX founder Sam Bankman-Fried "has been under house arrest at his parents' home on the Stanford campus since December," writes the Washington Post, "making the elite university the unlikely host to one of America's most notorious alleged white-collar criminals.

"Surrounded by student co-ops, fraternity houses and other faculty homes, he's the talk of the neighborhood." Bankman-Fried, the son of two Stanford law professors, was released on a $250 million bond secured by the Craftsman-style house. While awaiting his fraud trial later this year, Bankman-Fried wears an ankle bracelet to track his movements and plays with his new dog, Sandor, according to a Puck News report.... It remains to be seen what consequences Bankman-Fried, who pleaded "not guilty," might face. So far, his ability to be detained at home, instead of held in prison, is an exception to how most federal defendants are treated. The quiet, traffic-light Stanford neighborhood is quite the upgrade from Fox Hill, a notoriously rough prison in the Bahamas where Bankman-Fried was briefly held before being extradited.

If Bankman-Fried violates the terms of his bail agreement, his parents could lose their house, which they've owned since 1991 and is worth over $3.5 million, according to public property records....

The U.S. government has tried to restrict his access to virtual private networks and certain apps where messages disappear, but a final ruling has not been made. The judge presiding over his case asked in a hearing last month, "Why am I being asked to turn him loose in this garden of electronic devices?," highlighting that despite any restrictions the court might place on Bankman-Fried's use of technology, he remains in a home with his parents who also have a plethora of ways to be wired. On Friday, prosecutors proposed limiting Bankman-Fried to a flip-phone or "non-smartphone" that cannot access the internet, and that he be issued a new laptop "with limited functionalities." Prosecutors also want to place strict limits and monitoring tools on his parents' devices.

But meanwhile, among the student population, "There are party fliers with his likeness. He's a punchline in campus comedy sketches. Students ride their bikes by on dates.... When asked whether they could confirm a rumor that a nearby student co-op had attacked the Bankman-Fried home with eggs, Stanford campus police did not respond."

And one freshman/cryptocurrency enthusiast even stole a sign from in front of Bankman-Fried's house, then "paraded it around for selfies at a cryptocurrency networking event. The sign is currently growing mold in his dorm-room closet." Bankman-Fried, who grew up on campus, "certainly fits into what I regard as the kind of culture of Stanford," says Richard White, a retired Stanford history professor — even if the 30-year-old former billionaire left Silicon Valley to attend MIT. White and others characterize Stanford's culture as a place where faculty and students are emboldened to take big risks in conceiving the next hot start-up or breakthrough innovation, often with easy access to capital, the conviction that they're changing the world — and few consequences if things go south.
"Through his spokesman Mark Botnick, Bankman-Fried declined to comment for this article...."
The Courts

Fake DMCA Takedowns Blocking Journalists' Stories (bbc.co.uk) 47

The BBC reports: Journalists have been forced to temporarily take down articles critical of powerful oil lobbyists due to the exploitation of US copyright law, according to a new report.

At least five such articles have been subject to fake copyright claims, including one by the respected South African newspaper Mail & Guardian, according to the Organized Crime and Corruption Reporting Project (OCCRP). The claims — which falsely assert ownership of the stories — have been made by mystery individuals under the US Digital Millennium Copyright Act (DMCA), a law meant to protect copyright holders. Just last month, three separate false copyright claims were made against Diario Rombe, an investigative news outlet that focusses on Equatorial Guinea. The articles under attack are about the president of Equatorial Guinea's son, Gabriel Mbaga Obiang Lima, and his close associate, Cameroonian businessman and lawyer NJ Ayuk.

The OCCRP claimed in a report published on Wednesday that the DMCA process was often abused by "unknown parties" who create backdated fake articles to target critical news reports....

Climate Home editor Megan Darby told the OCCRP: "These bogus allegations look like a devious tactic to suppress independent journalism."

Thanks to Slashdot reader Bruce66423 for sharing the story.
Censorship

Roald Dahl eBooks Reportedly Censored Remotely (thetimes.co.uk) 244

"Owners of Roald Dahl ebooks are having their libraries automatically updated with the new censored versions containing hundreds of changes to language related to weight, mental health, violence, gender and race," reports the British newspaper the Times. Readers who bought electronic versions of the writer's books, such as Matilda and Charlie and the Chocolate Factory, before the controversial updates have discovered their copies have now been changed.

Puffin Books, the company which publishes Dahl novels, updated the electronic novels, in which Augustus Gloop is no longer described as fat or Mrs Twit as fearfully ugly, on devices such as the Amazon Kindle. Dahl's biographer Matthew Dennison last night accused the publisher of "strong-arming readers into accepting a new orthodoxy in which Dahl himself has played no part."

Meanwhile...
  • Children's book author Frank Cottrell-Boyce admits in the Guardian that "as a child I disliked Dahl intensely. I felt that his snobbery was directed at people like me and that his addiction to revenge was not good. But that was fine — I just moved along."

But Cottrell-Boyce's larger point is "The key to reading for pleasure is having a choice about what you read" — and that childhood readers faces greater threats. "The outgoing children's laureate Cressida Cowell has spent the last few years fighting for her Life-changing Libraries campaign. It's making a huge difference but it would have a been a lot easier if our media showed a fraction of the interest they showed in Roald Dahl's vocabulary in our children."


The Courts

Scooter Startup Lime Sues Hertz For Poaching Engineers (reuters.com) 32

Urban scooter company Lime sued Hertz Corp on Thursday alleging unfair competition and accusing the rental car giant of improperly hiring the startup's senior engineers. Reuters reports: San Francisco-based Neutron Holdings Inc, which does business as Lime, filed the lawsuit (PDF) in California federal court seeking unspecified monetary damages and an injunction "to recover and protect its trade secrets." It also named Charlie Fang, who previously was Lime's head of engineering, and another engineer as defendants. Lime claimed that Fang, who joined Hertz last year as a senior vice president, violated his employment agreement to not solicit former colleagues after leaving the company.

Hertz said in a statement it "vehemently disagrees with the claims made in the lawsuit." The loss of engineers has "significantly harmed" Lime, which provides short-term e-bike and scooter rentals in about 30 countries. The company said in the lawsuit it now faces "staff shortages, recruiting costs, and critical project delays." Hertz sought to "capitalize" on Fang and his team's knowledge of building "back-end infrastructure for ride-sharing and consumer facing apps so that it could gain a competitive advantage over other companies," according to the complaint.

Privacy

San Diego Police Want To Add Surveillance Tech: 500 Streetlight Cameras Plus License Plate Readers (sandiegouniontribune.com) 24

San Diego Union-Tribune: Almost three years ago, the city of San Diego cut off access to its broad network of Smart Streetlights -- more than 3,000 devices perched atop light poles that could collect images and other data, some of which the Police Department used to solve criminal cases. The city removed that access, at least without a warrant, because of concerns from the public about surveillance and privacy issues. On Wednesday, the San Diego Police Department said it wants access to 500 of those devices to be restored -- and they want to add another crime-solving tool to the network: automated license plate readers.

The controversy surrounding the Smart Streetlights began in 2019 when it was revealed that the cameras had been installed without public input. Police started accessing the camera footage in 2018 for investigations. Direct access was cut off in 2020 as a result of public outcry. Because the Smart Streetlight cameras had not been well maintained over the years, the city would need to install new cameras. Adding the license plate reader technology would mark the first time the city of San Diego would have the readers in fixed locations. This is the first big push for surveillance technology in San Diego since the city approved ordinances last year specifically setting rules to govern this kind of technology in light of privacy concerns.

Social Networks

Reddit Tells Court: Film Studios Spewed 'Nonsense' in Demand for Users' Names (arstechnica.com) 36

Reddit is fighting a film-industry attempt to identify users who discussed piracy, telling a federal court that the studios' request for users' real names should be rejected and that one of the studios' arguments is "nonsense." From a report: "Courts have long recognized that the First Amendment protects online anonymity and have established a stringent standard to use in precisely this scenario, where a litigant seeks to unmask users for the purpose of providing evidence in litigation that does not involve those users... Plaintiffs are far from meeting that strict standard here," Reddit said Tuesday in a filing in US District Court for the Northern District of California.

Reddit has no involvement in the lawsuit that triggered the request for users' identities -- the studios behind films such as Hellboy, Rambo V: Last Blood, Tesla, and The Hitman's Bodyguard sued cable broadband provider RCN in a different court, alleging that RCN failed to terminate Internet subscribers who illegally downloaded copyrighted movies. (RCN is now known as Astound Broadband after being combined with several other cable ISPs in the same ownership group.) In an attempt to prove that RCN turned a blind eye to users downloading copyrighted movies, the film studios subpoenaed Reddit seeking identifying information for specific users who commented in piracy-related threads. After Reddit provided information on only one user, calling the other requests a "fishing expedition," the studios filed a motion to compel Reddit to respond to the subpoena.

AI

AI Adviser 'Hired' By the Romanian Government To Read People's Minds (vice.com) 18

An anonymous reader quotes a report from Motherboard: A new AI assistant has been unveiled by the Romanian prime minister, which he hopes will inform the government about Romanians' wishes "in real time". Nicolae Ciuca claimed that Ion (Romanian for 'John') is his "new honorary adviser" and an "international first" on Wednesday at the start of a governmental meeting. He also said that Romanians would also be able to chat directly with Ion on the project's website. "Hi, you gave me life and my role is now to represent you, like a mirror. What should I know about Romania?" Ion's voice said at the launch. Ion takes a physical form as a long, mirror-like structure with a moving graphic at the top suggesting it is listening at all times. "I have the conviction that the use of AI should not be an option but an obligation to make better-informed decisions," Ciuca said.
Privacy

BetterHelp Sold Customer Data While Promising It was Private, Says FTC (theverge.com) 38

Online counseling company BetterHelp has agreed to pay $7.8 million to settle charges from the Federal Trade Commission that it improperly shared customers' sensitive data with companies like Facebook and Snapchat, even after promising to keep it private. The Verge reports: The proposed order, announced by the FTC on Thursday, would ban the same behavior in the future and require BetterHelp to make some changes to how it handles customer data. According to the regulator, the sign-up process for the company's service "promised consumers that it would not use or disclose their personal health data except for limited purposes." However, the FTC alleges that the company instead "used and revealed consumers' email addresses, IP addresses, and health questionnaire information to Facebook, Snapchat, Criteo, and Pinterest for advertising purposes."

The FTC also says that the company gave customer service agents false scripts to try and reassure users that it wasn't sharing personally identifiable or personal health information after a February 2020 report from Jezebel exposed some of its practices. The commission's complaint (PDF) accuses the company of misleading customers by putting a HIPAA seal on its website, despite the fact that "no government agency or other third party reviewed [BetterHelp]'s information practices for compliance with HIPAA, let alone determined that the practices met the requirements of HIPAA."

If the FTC's order ends up going through, the $7.8 million would go to customers who signed up for the service between August 1st, 2017, and December 31st, 2020. Here are some of the other things BetterHelp would be required to do:

- Stop sharing individually identifiable information about consumer's mental health with any third parties
- Stop misrepresenting its data collection and use policies
- Alert customers who created accounts before January 1st, 2021, that their personal info may have been used for advertising
- Obtain "affirmative express consent" from a customer before sharing information with a third party
- Reach out to third parties that received customer information and ask that it be deleted
- Establish a "comprehensive privacy program" and have an independent third party carry out privacy assessments

AI

UK Argues AI Is No More of an Inventor Than Your Cat (bloomberg.com) 43

If an artificial intelligence machine can be named as an inventor for a patent, pet cats could be next, lawyers said at the UK's top court arguing only humans can be inventors in law. From a report: The UK's Supreme Court will decide whether an AI machine can be named as an inventor and who may own the patent. Imagination Engines founder, Stephen Thaler, challenged the rejection of his patent applications naming his AI machine as inventor for a beverage container and a flashing light. Allowing an AI machine to be named as the inventor can open doors to "plainly ridiculous assertion," Stuart Baran, a lawyer for the patent office, said in documents prepared for the case. Should the judges rule in favor of Thaler inventors could include "my cat Felix" or "cosmic forces," he said. Thaler tried registering the patent naming his system, DABUS, as inventor in several countries but was successful only in Australia and South Africa, according to the court documents.
Piracy

BitTorrent Seedbox Provider Handed Criminal Conviction Over Users' Piracy (torrentfreak.com) 25

A man who rented out servers configured for BitTorrent file-sharing use has been handed a three-month suspended sentence in Denmark. Known as 'seedboxes', these pre-configured servers are not illegal per se, but when customers used the devices to break copyright law on known pirate sites, rightsholders held the server provider liable. TorrentFreak reports: Local anti-piracy group Rights Alliance (Rettigheds Alliancen) mitigates all types of piracy but for the past few years, has maintained a keen focus on torrent sites. Working in partnership with the Danish government's SOIK IP-Task Force, Rights Alliance forced several sites to close down and successfully prosecuted site operators, staff members, and users who uploaded content to those sites. In 2021, Rights Alliance targeted specialized servers that not only supply content to torrent sites but also play a role in boosting download times while improving security.

In 2021, news broke that six people had been arrested in Denmark due to their alleged connections to several local torrent sites. Among them was Kasper Nielsen of internet services company HNielsen Networks, a supplier of servers under various brands that could be configured for 'seedbox' purposes. Available information indicated that the servers had been used by an unknown number of users to share content on private torrent sites ShareUniversity, Superbits and DanishBytes. [...] When Rights Alliance filed its criminal complaint against HNielsen Networks, the anti-piracy group referenced the landmark Filmspeler case which involved the sale of piracy-configured media players.

According to statements published by Rights Alliance and NSK (Saerlig Kriminalitet) Denmark's Special Crime Unit, Nielsen was convicted yesterday for selling seedboxes in the knowledge they were being used by others to share movies, TV shows, eBooks and other content, without permission from rightsholders. "On February 28, the Court in Aalborg ruled against the Danish owner behind a seedbox company for, in the period November 2020 to May 2021, having sold seedboxes and server capacity to an unknown number of people, knowing that they were used for illegal sharing of no less than 3,838 copyright-protected works on the Danish and Nordic file sharing services ShareUniversity, Superbits and DanishBytes," Rights Alliance reports. Nielsen was handed a three-month conditional (suspended) sentence and a confiscation order for DKK 300,000 (around $42,600), the amount users had paid his company to access the seedbox servers. The 35-year-old must also pay compensation of DKK 298,660 to Rights Alliance.
"Providers of seedboxes have a responsibility to ensure that their services are not used for illegal uploading and downloading of copyrighted content, which the Rights Alliance can clearly see that they are doing," says Maria Fredenslund, Director of Rights Alliance. "Therefore, this case helps to send a signal to other providers that you cannot deliberately sell services to the illegal market."

Since Neilsen took a plea deal at an early stage, none of the claims made by Rights Alliance were needed to be proven in court. "The 3,838 figure and any evidence related to 'knowledge' of infringement carried out by seedbox customers on the sites, were accepted as true," reports TorrentFreak.
Government

'Havana Syndrome' Not Caused By Energy Weapon or Foreign Adversary, US Intelligence Says (theguardian.com) 68

An anonymous reader quotes a report from The Guardian: The mysterious set of symptoms known as "Havana syndrome" was not caused by an energy weapon or foreign adversary, US intelligence has concluded. The assessment concludes a multi-year investigation into approximately 1,000 "anomalous health incidents" (AHIs) among US diplomats, spies and other employees in US embassies and missions around the world. Victims reported brain injuries, hearing loss, vertigo and strange auditory sensations, among other symptoms. Many suspected they had been victims of a targeted attack using some kind of directed energy weapon.

Of the seven intelligence agencies that undertook the investigation, five determined that "available intelligence consistently points against the involvement of US adversaries in causing the reported incidents," according to an unclassified version of the report released Wednesday by the House intelligence committee. Those five agencies deemed foreign adversary involvement "very unlikely." One considered it "unlikely" and one declined to state a conclusion.

The assessment involved a painstaking effort to analyze syndrome cases for patterns that could link them, as well as a search, using forensics and geolocation data, for evidence of a directed energy weapon, unnamed officials told the Post. "There was nothing," one official said. The officials told the Post they were open to new evidence that a foreign adversary had developed an energy weapon, but did not believe Russia or any other adversary was involved in these cases. The intelligence agencies "judge that there is no credible evidence that a foreign adversary has a weapon or collection device that is causing AHIs", according to the unclassified report.
"In light of this and the evidence that points away from a foreign adversary, causal mechanism, or unique syndrome linked to AHIs, IC agencies assess that symptoms reported by US personnel were probably the result of factors that did not involve a foreign adversary, such as preexisting conditions, conventional illnesses, and environmental factors," the report reads.

Three agencies have "high confidence" in that assessment, three have "moderate confidence" and one has "low confidence."
Patents

Dell and Partners Smash Patent Troll WSOU in Court (beehiiv.com) 37

In the land of patent litigation, all patent trolls want to file in the US Western District of Texas Court. This court is infamous for being sympathetic to patent plaintiffs. That's why patent litigator WSOU Investments, aka Brazos Licensing and Development, went after Dell, EMC, and VMware in this Court. Usually, this would have been the smart move. Not this time. District Judge Alan Albright granted the defendants a directed verdict, and that was the end of the matter. From a report: What happened was this: WSOU, although successful before with their carpet bombing patent lawsuit strategy, failed this time. According to the lead defense counsel and Gibson Dunn partner, Brian A. Rosenthal, "This case got to trial because the plaintiff refused to come to their senses before trial. We obtained a number of serious exclusions of evidence prior to trial, and told them very early on the case had no merit." The judge agreed.

That came as a surprise to those of us who watch patent lawsuits, so you don't have to. As Heather Meeker, the well-known open-source and intellectual property (IP) lawyer, said, "This is surprisingly defendant-friendly from Judge Albright, who has received a lot of criticism for making Waco such a patent plaintiff-friendly docket." Until now, WSOU had been very successful. As a Patent Assertion Entity (PAEs), its only goal is to profit by acquiring patents and then suing companies that might be using the patents' intellectual property (IP) assets. It does this by using its portfolio of technology patents to file numerous individual suits involving different patents against companies. WSOU's main tactic, as Unified Patents put it, "forces operating companies to either settle or fight, on average, eight lawsuits at once."

Most companies faced with the financial burden of struggling with so many lawsuits settle rather than fight. Not this time. For the first time, companies decided to take the issues to court. In this particular set of cases, WSOU claimed in a June 2020 lawsuit that the defendants had infringed on three cloud infrastructure networking patents, and sought $435 million in damages. Rosenthal argued that the patents in question were old and irrelevant to the defendants' interests. The defense team had informed WSOU in October 2020 that there was no proof of direct infringement, but the plaintiff persisted with the case, leading to exclusions of evidence prior to trial. So it was that on the first day of the trial, two of the patents were tossed out on evidentiary rulings, and the plaintiff rested its case on the third day. The defense then requested a directed verdict, which was granted by Albright, resulting in a win for the defendants. In short, even this patent-friendly court could find no evidence at all for WSOU's assertions.

Crime

FTX Ex-Engineering Chief Nishad Singh Pleads Guilty To Criminal Charges (cnbc.com) 19

FTX ex-engineering head Nishad Singh pleaded guilty to criminal charges in New York on Tuesday, becoming the latest member of Sam Bankman-Fried's former leadership team to agree to a deal. CNBC reports: The six charges against Singh include conspiracy to commit securities fraud, conspiracy to commit money laundering and conspiracy to violate campaign finance laws. FTX spiraled into bankruptcy in November after the crypto exchange, founded by Bankman-Fried, couldn't meet customers' withdrawal demands.

"Today's guilty plea underscores once again that the crimes at FTX were vast in scope and consequence," Manhattan U.S. Attorney Damian Williams said in a statement. "They rocked our financial markets with a multibillion dollar fraud. And they corrupted our politics with tens of millions of dollars in illegal straw campaign contributions. These crimes demand swift and certain justice and that is exactly what we are seeking in the Southern District of New York."

The Securities and Exchange Commission, as well as the Commodity Futures Trading Commission both filed related civil complaints against Singh on Tuesday. The SEC said in a release that Singh is cooperating with the agency's ongoing investigation, and he has separately agreed to settle with the CFTC. Two of the criminal charges against Singh are related to wire fraud and another is conspiracy to commit commodities fraud.

Privacy

Hackers Claim They Breached T-Mobile More Than 100 Times In 2022 (krebsonsecurity.com) 14

An anonymous reader quotes a report from KrebsOnSecurity: Three different cybercriminal groups claimed access to internal networks at communications giant T-Mobile in more than 100 separate incidents throughout 2022, new data suggests. In each case, the goal of the attackers was the same: Phish T-Mobile employees for access to internal company tools, and then convert that access into a cybercrime service that could be hired to divert any T-Mobile user's text messages and phone calls to another device. The conclusions above are based on an extensive analysis of Telegram chat logs from three distinct cybercrime groups or actors that have been identified by security researchers as particularly active in and effective at "SIM-swapping," which involves temporarily seizing control over a target's mobile phone number.

Countless websites and online services use SMS text messages for both password resets and multi-factor authentication. This means that stealing someone's phone number often can let cybercriminals hijack the target's entire digital life in short order -- including access to any financial, email and social media accounts tied to that phone number. All three SIM-swapping entities that were tracked for this story remain active in 2023, and they all conduct business in open channels on the instant messaging platform Telegram. KrebsOnSecurity is not naming those channels or groups here because they will simply migrate to more private servers if exposed publicly, and for now those servers remain a useful source of intelligence about their activities.

Each advertises their claimed access to T-Mobile systems in a similar way. At a minimum, every SIM-swapping opportunity is announced with a brief "Tmobile up!" or "Tmo up!" message to channel participants. Other information in the announcements includes the price for a single SIM-swap request, and the handle of the person who takes the payment and information about the targeted subscriber. The information required from the customer of the SIM-swapping service includes the target's phone number, and the serial number tied to the new SIM card that will be used to receive text messages and phone calls from the hijacked phone number. Initially, the goal of this project was to count how many times each entity claimed access to T-Mobile throughout 2022, by cataloging the various "Tmo up!" posts from each day and working backwards from Dec. 31, 2022. But by the time we got to claims made in the middle of May 2022, completing the rest of the year's timeline seemed unnecessary. The tally shows that in the last seven-and-a-half months of 2022, these groups collectively made SIM-swapping claims against T-Mobile on 104 separate days -- often with multiple groups claiming access on the same days.
In a written statement to KrebsOnSecurity, T-Mobile said this type of activity affects the entire wireless industry.

"And we are constantly working to fight against it," the statement reads. "We have continued to drive enhancements that further protect against unauthorized access, including enhancing multi-factor authentication controls, hardening environments, limiting access to data, apps or services, and more. We are also focused on gathering threat intelligence data, like what you have shared, to help further strengthen these ongoing efforts."
Piracy

You Can Watch Pluto TV in VLC, and the MPA Considers This Piracy (theverge.com) 67

The Motion Picture Association (MPA) issued a DMCA notice to a GitHub repo that contained a playlist that let viewers watch Pluto TVs streams on their own apps, such as VLC, MPV, and Tvheadend. From a report: The move was first noticed by TorrentFreak, and GitHub has complied and removed the repo, which ultimately does nothing. If you still have a tiny text file, you can still do exactly what the MPA tried to stop. Pluto TV, for those who do not watch it, is a service owned by Paramount that allows users to legally stream movies and TV shows free of charge on many devices. They have a mobile app, apps for Xbox and PlayStation, smart TVs, and dongles. Users do not even need to sign up to use it. In turn, Pluto's business model is predicated on serving ads and tracking user behavior. It's part of a newer breed of streaming product called free ad-supported television, or FAST. The GitHub repo in question contained M3U playlists to watch Pluto TV's content via an app like VLC. The repo basically took links that were already available and gathered them in one place. It should be noted that M3U files aren't torrent files; it's just a simple playlist file that can direct to local files and web sources.
The Internet

Governments Shut Down the Internet More Often Than Ever, Report Says 27

More countries shut down the internet in 2022 than ever before, according to a new report by digital rights researchers, as the threat of "digital authoritarianism" races up the agenda of many governments worldwide. From a report: Authorities in 35 countries instituted internet shutdowns at least 187 times, according to the New York-based digital rights watchdog Access Now. Nearly half of these shutdowns occurred in India, and if that nation is excluded, 2022 saw the most number of shutdowns globally since the group began monitoring disruptions in 2016. Access Now relied on technical assessments as well as news articles and personal accounts to compile its report, which spans complete blackouts, suspensions of specific phone networks or social media apps, and the slowing down of internet speeds.

Triggers for shutdowns have included large protests, conflict situations, elections and even examinations. Whatever the situation, they make it substantially more difficult for people to communicate and receive or send news, and they incur significant economic costs, which prompted the United Nations last year to call for governments to avoid using such a blunt tactic. "This can be a big warning sign of how the human rights situation is deteriorating, and shutdowns are often associated with increased levels of insecurity and other restrictions," said Liz Throssell, a spokeswoman at the U.N. Human Rights Office in Geneva. India is the most prolific at suspending the internet, topping Access Now's list for the fifth year in a row.
Government

Huawei Export Licenses Could be Revoked by US (wsj.com) 24

The Biden administration is considering revoking export licenses issued to U.S. suppliers for sales to Chinese telecom company Huawei, WSJ reported Tuesday, citing people familiar with the matter, part of a broader tightening of technology trade over national security concerns. From a report: The administration previously indicated that it was considering not granting any new export licenses to companies such as Qualcomm and Intel, which provide chips needed for smartphones and other devices. The action would cover products that use advanced 5G technology as well as older 4G products. The new action would take that a step further by revoking existing licenses. It comes amid heightened U.S.-China tensions triggered by a suspected Chinese spy balloon traversing the U.S. and intelligence suggesting Beijing is considering provision of lethal aid to Russia for its Ukraine war.

"The policy that had allowed exports to Huawei, notwithstanding the entity listing, is being wound down," said a former senior security official familiar with the administration's policy deliberations. "The White House is now telling Commerce, 'Cut off the 4G sales, the time has come to do more pain to Huawei, to try to finish their demise,'" the former official said. Huawei was placed on the Commerce Department's so-called entity list in 2019 by the office that oversees export controls, the Bureau of Industry and Security. The BIS cited potential national-security threats when it issued the punitive listing, which requires exporters to secure special licenses approving the sale of U.S. technology to the firm. U.S. officials say they are concerned China's government could use Huawei's telecommunications tech for spying.

Security

US Marshals Service Suffers 'Major' Security Breach That Compromises Sensitive Information (nbcnews.com) 29

According to a spokesperson for the United States Marshals Service (USMS), the agency was hit with a ransomware attack last week that compromises sensitive information. NBC News reports: In a statement Monday, U.S. Marshals Service spokesperson Drew Wade acknowledged the breach, telling NBC News: "The affected system contains law enforcement sensitive information, including returns from legal process, administrative information, and personally identifiable information pertaining to subjects of USMS investigations, third parties, and certain USMS employees."

Wade said the incident occurred Feb. 17, when the Marshals Service "discovered a ransomware and data exfiltration event affecting a stand-alone USMS system." The system was disconnected from the network, and the Justice Department began a forensic investigation, Wade said. He added that on Wednesday, after the agency briefed senior department officials, "those officials determined that it constitutes a major incident." The investigation is ongoing, Wade said.

A senior law enforcement official familiar with the incident said the breach did not involve the database involving the Witness Security Program, commonly known as the witness protection program. The official said no one in the witness protection program is in danger because of the breach. Nevertheless, the official said, the incident is significant, affecting law enforcement sensitive information pertaining to the subjects of Marshals Service investigations. The official said the agency has been able to develop a workaround so it is able to continue operations and efforts to track down fugitives.

Slashdot Top Deals